Interesting post this.
Consider the following scenario: While it may be easy to see that a user is part of Active Directory "Group X," what access clearance does that group actually provide? What policies are in place to ensure that the user should get access to specific applications via the virtual product? If the IT team adds a user to Group X in order to give them access via a virtualization application, what other access do they get by being associated with this group? If these questions haven't been asked yet, you can be sure this is the next question your auditor will ask – "How did this user get access and why?"
Read further...
Comments
Post a Comment